{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 182 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24738-security-advisory-0182"
      }
    ],
    "title": "Security Advisory 182",
    "tracking": {
      "current_release_date": "2026-09-17T11:49:06Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 182",
      "initial_release_date": "2026-09-17T11:49:06Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:49:06Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "SD-WAN version release_7.0.0",
                    "product": {
                      "name": "SD-WAN version release_7.0.0",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "SD-WAN version 1.0.0",
                    "product": {
                      "name": "SD-WAN version 1.0.0",
                      "product_id": "CSAFPID-1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "SD-WAN"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-86109",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1833886"
      },
      "notes": [
        {
          "category": "description",
          "text": "The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "Exploitation requires control over the software-update package or associated update metadata delivered to the Edge. This could result from compromise of the VeloCloud Orchestrator or high-privilege access sufficient to stage, replace, or control an Edge software-update package.",
          "title": "1833886: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-1"
        ],
        "fixed": [
          "CSAFPID-0"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86109"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in SD-WAN version release_7.0.0",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in SD-WAN version 1.0.0",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "mitigation",
          "details": "Until an upgrade can be completed, customers should continue to follow operational best practices, including:\n\n* Restrict software-image management and VeloCloud Edge update privileges to trusted administrators.\n* Protect VeloCloud Orchestrator administrative credentials and management access.\n* Obtain and distribute VeloCloud Edge software only through trusted Arista management and distribution channels.\n* Investigate unexpected software images or update operations before permitting installation.\n\nThese measures reduce exposure but do not correct the vulnerable update-verification workflow."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-86109"
    }
  ]
}